Global Cybersecurity Index An overview
Rosheen Awotar-Mauree Programme Officer ITU Office for Europe
Global Cybersecurity Index An overview Rosheen Awotar-Mauree - - PowerPoint PPT Presentation
Global Cybersecurity Index An overview Rosheen Awotar-Mauree Programme Officer ITU Office for Europe What is GCI GCI is a composite index combining 25 indicators into one benchmark measure to monitor and compare the level of ITU Member
Rosheen Awotar-Mauree Programme Officer ITU Office for Europe
GCI is a composite index combining 25 indicators into one benchmark measure to monitor and compare the level of ITU Member States
the High-Leve Experts and endorsed by the GCA.
All iterations include primary research in order to provide global coverage of the 194 Member States
The GCIv3 includes 25 indicators and 50 questions. The indicators used to calculate the GCI were selected on the basis of the following criteria:
Cybersecurity Agenda) pillars and in contributing towards the main GCI
and conceptual framework;
cross verification through secondary data.
Legal
legislation
regulation
training on regulation and laws Technical
CIRT
implementation framework for
certification for professionals Organizational
agency
metrics Capacity Building
bodies
programmes
awareness campaigns
training courses
education programmes and academic curricula
mechanisms
cybersecurity industry Cooperation
agreements
agreements
fora participation
partnerships
partnerships
What makes the GCI unique is the balanced combination of:
Index from different organizations and companies are researched and compared
provided by GCI Partners
19.12 2.1. Is there a CIRT, CSIRT or CERT with national responsibility? 4.65 2.1.1.Does it have a government mandate? 1.33 2.1.2.Does the CIRT, CSIRT or CERT conduct recurring cybersecurity exercise? 1.23 2.1.3.Is the CIRT, CSIRT or CERT affiliated with FIRST? 1.04 2.1.4.Is the CIRT, CSIRT or CERT affiliated with any other CERT communities? (regional CERT) 1.06 2.2. Is there a Government CERT? 3.03 2.3. Are there any sectoral CERTs? 2.71
20.94
19.12
19.67
18.93
21.34
Total of all weightages = 100
Global Report Regional Report Cyberwellness Profiles Factual information on cybersecurity achievements on each country
Commitment levels High Medium Low
Country GCI Score Legal Technical Organizational Capacity Building Cooperation Singapore 0.92 0.95 0.96 0.88 0.97 0.87 United States 0.91 1 0.96 0.92 1 0.73 Malaysia 0.89 0.87 0.96 0.77 1 0.87 Oman 0.87 0.98 0.82 0.85 0.95 0.75 Estonia 0.84 0.99 0.82 0.85 0.94 0.64 Mauritius 0.82 0.85 0.96 0.74 0.91 0.70 Australia 0.82 0.94 0.96 0.86 0.94 0.44 Georgia 0.81 0.91 0.77 0.82 0.90 0.70 France 0.81 0.94 0.96 0.60 1 0.61 Canada 0.81 0.94 0.93 0.71 0.82 0.70
Maximum score is 1
0.210 0.296 0.334 0.370 0.430 0.530 Regional Score on a maximum on 1
43 Countries EUROPE : Albania, Andorra, Austria, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Israel, Italy, Latvia, Liechtenstein, Lithuania,Luxembourg, Malta, The Former Yugoslav Republic of Macedonia, Monaco, Montenegro, Netherlands, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovak Republic, Slovenia, Spain, Sweden, Switzerland, Turkey, Vatican,United Kingdom 11 Countries CIS : Armenia, Azerbaijan, Belarus, Georgia, Kazakhstan, Moldova, Russian Federation, Tajikistan, Turkmenistan, Ukraine, Uzbekistan
demonstrate high commitment.
percentile) that have developed complex commitments, and engage in cybersecurity programmes and initiatives.
have started to make commitments in cybersecurity.
Out of 54 ✓ 24 countries have Cybercriminal legislation ✓ 32 countries have Cybersecurity legislation ✓ 20 countries have Cybersecurity training on regulation and laws ✓ 35 countries have National CIRTs ✓ 43 countries have Government CIRTs ✓ 34 countries have sectoral CIRTs ✓ 38 countries have an entity responsible for Child Online Protection ✓ 7 countries use Cybersecurity metrics at national level ✓ 12 countries have standardization bodies handling Cybersecurity ✓ 23 countries have good practices in Cybersecurity ✓ 17 countries have R&D programmes in Cybersecurity
Netherlands uses metrics annually in order to measure cybersecurity development at a national level, summarized in the Cyber Security Assessment Netherlands report. The National Cyber Security Centre (NCSC) compiles disclosure reports, security advisories and incidents using a registration system. The metrics allow trends to be observed and acted on.
UK and China agreed to establish a high-level security dialogue to strengthen exchanges and cooperation on security issues such as non-proliferation, organized crime, cyber crime and illegal
property, trade secrets or confidential business information with the intent of providing competitive advantage
United Kingdom issued in 2016 its second five years National Cyber Security Strategy. The strategy, issued by the Cabinet Office, aims to make the country one of the safest places in the world to carry
questions
Preparation phase Start phase Data collection phase Verification Phase Analysis Phase Report writing and publication Phase